New:Introducing Socket Scanning for VS Code Marketplace Extensions.Learn more →
Get Started

@pgsql/semantics

Package Overview
Dependencies
Maintainers
1
Versions
9
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@pgsql/semantics

AST-derived semantic facts for PostgreSQL statements: what each statement creates, references, and touches

latest
Source
npmnpm
Version
18.1.11
Version published
Weekly downloads
4.3K
-50.75%
Maintainers
1
Weekly downloads
 
Created
Source

@pgsql/semantics

AST-derived semantic facts for PostgreSQL statements: given a SQL script, extract what each statement is, what it creates, and what it references — including references reached inside PL/pgSQL function bodies (via plpgsql-parser hydration). Read-only: the input is never modified.

This is the fact-extraction layer that grew up inside @pgsql/transform. It extracts semantics (which relations/functions/types a statement reads and creates, which namespaces it touches), independent of any transformation. @pgsql/transform re-exports the same symbols, so existing consumers are unaffected.

Installation

npm install @pgsql/semantics

The parser runs on a WASM build of the real PostgreSQL parser; call loadModule() from plpgsql-parser once before using any synchronous API.

Usage

import { loadModule } from 'plpgsql-parser';
import { classifyStatements } from '@pgsql/semantics';

await loadModule();

const facts = classifyStatements(sql);
// per statement: kind (schema|table|view|index|type|function|trigger|policy|grant|...),
// creates, references (incl. inside PL/pgSQL bodies), bodyReferences,
// referencedSchemas, roles, fkTargets, extension, securityRelevant,
// securityDefiner, dynamicSql, span, stmt

Exports

  • classifyStatements(sql) — classify each top-level statement into StatementFacts[].
  • Types: StatementFacts, StatementKind, QualifiedName, ExtensionFact, ExtensionAction, StatementSpan.

🛠 Built by the Constructive team — creators of modular Postgres tooling for secure, composable backends. If you like our work, contribute on GitHub.

  • pgpm: A Postgres Package Manager that brings modular development to PostgreSQL with reusable packages, deterministic migrations, recursive dependency resolution, and tag-aware versioning.
  • pgsql-test: Instant, isolated PostgreSQL databases for each test with automatic transaction rollbacks, context switching, and clean seeding for fast, reliable database testing.
  • pgsql-seed: PostgreSQL seeding utilities for CSV, JSON, SQL data loading, and pgpm deployment.
  • pgsql-parser: The real PostgreSQL parser for Node.js, providing symmetric parsing and deparsing of SQL statements with actual PostgreSQL parser integration.
  • pgsql-deparser: A streamlined tool designed for converting PostgreSQL ASTs back into SQL queries, focusing solely on deparser functionality to complement pgsql-parser.
  • @pgsql/parser: Multi-version PostgreSQL parser with dynamic version selection at runtime, supporting PostgreSQL 15, 16, and 17 in a single package.
  • @pgsql/types: Offers TypeScript type definitions for PostgreSQL AST nodes, facilitating type-safe construction, analysis, and manipulation of ASTs.
  • @pgsql/enums: Provides TypeScript enum definitions for PostgreSQL constants, enabling type-safe usage of PostgreSQL enums and constants in your applications.
  • @pgsql/utils: A comprehensive utility library for PostgreSQL, offering type-safe AST node creation and enum value conversions, simplifying the construction and manipulation of PostgreSQL ASTs.
  • @pgsql/traverse: PostgreSQL AST traversal utilities for pgsql-parser, providing a visitor pattern for traversing PostgreSQL Abstract Syntax Tree nodes, similar to Babel's traverse functionality but specifically designed for PostgreSQL AST structures.
  • pg-proto-parser: A TypeScript tool that parses PostgreSQL Protocol Buffers definitions to generate TypeScript interfaces, utility functions, and JSON mappings for enums.
  • libpg-query: The real PostgreSQL parser exposed for Node.js, used primarily in pgsql-parser for parsing and deparsing SQL queries.

Disclaimer

AS DESCRIBED IN THE LICENSES, THE SOFTWARE IS PROVIDED "AS IS", AT YOUR OWN RISK, AND WITHOUT WARRANTIES OF ANY KIND.

No developer or entity involved in creating Software will be liable for any claims or damages whatsoever associated with your use, inability to use, or your interaction with other users of the Software code or Software CLI, including any direct, indirect, incidental, special, exemplary, punitive or consequential damages, or loss of profits, cryptocurrencies, tokens, or anything else of value.

Keywords

sql

FAQs

Package last updated on 07 Oct 2026

Related posts